Set up or audit identity and access management against the Singapore Government's ICT&SS Policy Reform (IM8 successor) Access Control controls (AC-1..AC-16): account inventory and deny-by-default least privilege, MFA for privileged accounts, Singpass/Corppass for public users vs government SSO (WOG AAD) for internal users, inactive/expired account handling, access reviews, automated account lifecycle, static credential rotation, endpoint hardening/MDM, identity- and device-based access, and separation of duties.